A management system that has been designed properly and brought into use should pass its first audit. The harder question is whether anybody is still running it when the auditor comes back. I build systems your own people will choose to engage with, and I will tell you plainly when a standard is the wrong answer to the problem you actually have.
Four patterns I have watched play out while building and auditing management systems. My own view, not research, and frequent enough that I design against them from the first conversation.
A suite of documents arrives, gets signed off, and goes into a folder. Ask anyone inside the organisation why a given control is there and you will get a shrug. An auditor establishes that within the first ten minutes of a conversation.
A narrow scope passes cleanly. Then a client, a tender or an insurer asks a question the certificate does not cover, and the certificate stops being worth what it cost.
Audits get run to fill a schedule. The findings are cosmetic because a real finding would create work. The system stops telling anybody anything they did not already know.
Items from audits, reviews and incidents go on a register with an owner and a date, and stay there. At the surveillance visit the same items show up again with a later date against them.
The gap analysis comes first whatever your position. An organisation starting from nothing and an organisation whose system has drifted both need the same first answer, which is what the standard asks of them and how far off they are. What changes after that is how much of the work below is left to do.
What the standard asks of an organisation like yours, what you already do, and the distance between the two. Scored by clause, so the gap comes out as a list of jobs with my reasoning against each one. Everything that follows is built on this, and the rest of the work cannot be quoted honestly until it is done.
Built around how the business runs, in your own terms, with named owners. Where something you already do satisfies the standard, it stays and we write down why.
A certification body wants evidence that the system has been running, and that it found something. This is the stage organisations underestimate, and the one that decides how the audit goes.
Certification is awarded by a certification body, and I am not one. My job is getting you ready for them, being there on the day, and handling what comes out of it.
Certification is a project with an end date. Keeping the system alive afterwards runs for as long as you hold the certificate, which is why the two are priced and structured differently.
The gap analysis is quoted and done first. Once we both know the size of the job, the rest is scoped and quoted as a package against an agreed certification date, with no day rates running in the background.
Booked on its own. Useful before you commit to certification, and useful afterwards when the internal audit programme needs an auditor independent of the people who built the system.
A certificate lasts three years and asks for a surveillance visit each year. For a few organisations I run that cycle myself, a couple of days a month, alongside their wider risk, quality and compliance picture.
All four are built on the same structure, so an organisation holding one is a long way towards the next. Where you hold or want more than one, they are built as a single system with one set of policies, one audit programme and one management review. Separate suites end up contradicting each other.
Engagements are supported by our own gap-analysis and readiness tooling, so you can see maturity by clause, by section and over time, and know exactly what is left before an audit.
It also means a board paper takes minutes, and that the answer to "are we ready" is a number with working behind it.
All conversations are treated as strictly confidential. If a standard is the wrong answer for you, I would rather say that in the first conversation than after you have paid for it.